Hunting Hypothesis
Definition
A testable statement specifying what adversary behaviour might be present, which data source would show it, and what analytic would surface it. A hypothesis is the starting point for every structured hunt and must be specific enough to produce a falsifiable query.
- Definition
- Testable statement of possible adversary behaviour
- Required components
- Behaviour, data source, and analytic
- Key property
- Must be falsifiable and specific
- Role
- Starting point for a structured threat hunt
Common questions
How is a hunting hypothesis different from a SIEM alert rule?+
An alert rule fires automatically on a known signature or threshold, while a hunting hypothesis drives a human-led, exploratory investigation into behaviour that may not yet have a signature, often informed by threat intelligence or an intuition about a gap in existing detections.
Where do hunters typically source hypotheses from?+
Common sources include threat intelligence reporting on adversary tactics, MITRE ATT&CK technique coverage gaps, results of prior incidents, and anomalies noticed during routine monitoring that do not yet have an explanation.
What makes a hunting hypothesis too vague to be useful?+
A hypothesis like looking for suspicious activity gives no specific data source or analytic to apply, whereas a workable hypothesis names the behaviour, such as lateral movement via a specific protocol, the log source that would show it, and the query or analytic that would surface it.
Related terms
- Dwell Time
- The period between an attacker gaining initial access and their detection. Reducing dwell time is a primary goal of threat hunting. The...
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- MITRE ATT&CK
- A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
- Tactics, Techniques, and Procedures (TTPs)
- A three-level description of adversary behaviour. Tactics are the high-level goals (initial access, persistence, exfiltration). Techniques are the specific methods (spear-phishing, pass-the-hash)....
- Threat Hunting
- A proactive, human-led process that searches for evidence of adversary activity in an environment under the assumption that automated controls have been...